URLhaus Database

You are currently viewing the URLhaus database entry for http://thepaperberry.com/wp-admin/protected_array/close_cdfp7j4k_zbyhscuv12/gcv4_4391/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:288701
URL: http://thepaperberry.com/wp-admin/protected_array/close_cdfp7j4k_zbyhscuv12/gcv4_4391/
URL Status:Offline
Host: thepaperberry.com
Date added:2020-01-15 02:19:02 UTC
Last online:2020-01-29 16:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Not blocked
DNS4EU :Not blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?):mail Yes (Ticket DCU002246060 created on 2020-01-15 02:20:05 UTC)
Takedown time:14 days, 13 hours, 51 minutes Bad (down since 2020-01-29 16:11:26 UTC)
Tags:doc emotet link epoch1 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-01-17Attachment 12708494_6463.docdoc 5fdb7d61180301320cd456321ad2994e5686e8b2fd66c8d40fe1a2a0b1a2e152Virustotal results 36.67% Heodo
2020-01-1722448-977413.docdoc 4540d13474d9a5d7586a40a104739adf516fcf2cd77ab0ce4a2e8ccd8570df61Virustotal results 36.07% Heodo
2020-01-17095934.docdoc de8bd947fc8203ef4899153c36ae350b2e4b4e69db34daee230ad89442f13951Virustotal results 36.67% Heodo
2020-01-16Attachments 08103666.docdoc 0bb667859f35e9606b929fc129f045343481b1b7c72662a2b4e1d2a2dc778ec6Virustotal results 36.07% 
2020-01-16477575_688.docdoc 423dc90cfc54412bec01a810b9c3891a3013848255aab49b9fd3f04e0f8c91a0Virustotal results 37.10% Heodo
2020-01-16Attachments 259168_77163.docdoc 90a3beebaa0854035394ebb503a93b46b7858f539ac30bd19e1af068fecee85fVirustotal results 34.43% Heodo
2020-01-16Untitled 8639889.docdoc b92b45e9fbf925d3b824f34e0103e1acde36e461b07a297cb06fa182a6cdf146Virustotal results 32.79% Heodo
2020-01-16266990-241939.docdoc 889cf94d7f391e3a01900604efbf7e91709771a38594159de1dadc94553a5b26Virustotal results 32.26% Heodo
2020-01-161609387_3448.docdoc eafa9d9f6c1f32fb1009e0f1ac3907c1ed41ab1fe4d86717dc23a104e2cbeef7Virustotal results 29.51% Heodo
2020-01-16Untitled 2882606.docdoc 78ea94758e918e4115144dad9c8eab354f1e228174b8a00d49596e0afb2796c7Virustotal results 27.87% Heodo
2020-01-16Attachment 800206.docdoc 5b2a0117af3d95245f6c43ef539fbd170c31ccea1fe3a02d55e87e7fc761e2e0Virustotal results 28.81% 
2020-01-161420431-903195327.docdoc d01121be7f7eb193a85d9ba14596730d3d33089f5c368501a15b89dd095b803bVirustotal results 24.59% Heodo
2020-01-16Untitled 978895928_597.docdoc 5336e06637246298e68fe542f172f3b859b61f913d7b1b1f402dd43b9eab0aeaVirustotal results 26.67% Heodo
2020-01-16323.docdoc 41a33df5428a9b69eb9ca7bbed3dd8d8776d2243cf92c3ca20d20ff0745831c2Virustotal results 24.59% Heodo
2020-01-1695345607_959001.docdoc 058abfe0e47582efbe8082a02acb54eec587373096ba71b4f00150553e29a7faVirustotal results 24.59% Heodo
2020-01-1660422264_834549.docdoc 1ea26ae156e50ac1ddc42b7759789c5aa40697112afc006a4eec2131a9057186Virustotal results 22.95% Heodo
2020-01-168255644.docdoc 8a74acae6e18e058cb6298684509848286c3dc19189bb9f64e01f582cc31b919Virustotal results 20.97% Heodo
2020-01-164222-2926302706.docdoc 34ba96b376f260f361c61d4c896f95e584a1dc6aafd0fc609f6256f21d97b7ceVirustotal results 44.26% Heodo
2020-01-16Untitled 5338823525_56283.docdoc c570de6d4996adf000e474522d28c602a9c47b48e9dd69fa3861b4b88400a1c0Virustotal results 42.62% Heodo
2020-01-154035713464.docdoc 0be4320540734a39e0818810123c7202ea89e28cd8bf0a28c984bf0e58ab9689Virustotal results 40.00% 
2020-01-15Untitled 274_133622.docdoc 0dce7996d8fb1617ac09efd1125611ee679f96a6b1089fa6e2696a2ae84a726fVirustotal results 33.87% Heodo
2020-01-15Attachments 6589 27872194.docdoc 2a72d798a8c83d6eacf6b07c27ff4774da7d2b2a8b5e469cffaf22ac22a061a9Virustotal results 33.87% Heodo
2020-01-15FILE_8068552-8797.docdoc 2853b45864dd97b3be97f9acfcc6be83c6024d9b4e5b48d6b56a8c622e106b5eVirustotal results 32.26% Heodo
2020-01-15Untitled 3521292.docdoc 5a444bb7248957c2b190c22b974bb1d24c9d8c6b97f8467c1939c9addefaf35bVirustotal results 38.71% Heodo
2020-01-15attachment-20844350.docdoc 7e891b8bd1b0c2094a32fc750be95f01ca56c928d0eabae8d2a3e224620e6580Virustotal results 32.79% Heodo
2020-01-15Attachments-0842047-012713.docdoc 7892b2b70752b1d2ea7e1130decbd5d193738e9de5683b058c1124aa6b8ad1f9Virustotal results 32.79% Heodo
2020-01-15Attachments-8937774.docdoc 39bfeeabcf77b494d068ef3ac49576ebf99b16723fa1facf76e5b0b1752d99b4Virustotal results 30.65% Heodo
2020-01-15attachments.docdoc 2e08996c6b2e945284298d12fa32aa2f9095d766e0b2e67f6f3b8e07ee541810Virustotal results 25.00% Heodo
2020-01-15Untitled.docdoc 98bb0f81197453d87b17ace9204d09b4fd741c54e3791545ece0ecbf0e70a07dn/a Heodo
2020-01-15Untitled_file-0207306-934980.docdoc 789f9210cab6cd5d82f2eb8839d8f8681a18cd0e7cc05d4871ee30adf22833eaVirustotal results 22.95% Heodo
2020-01-15attachments 3532235.docdoc 609637f33b697bf3cf03c6198e03538893f491cef1aa0894fe101dae3bf4b67dVirustotal results 18.03% Heodo
2020-01-15Untitled_file_7195.docdoc c758eda50e69cf30766e229c8a0e31a6ffd61ce8c06ccce6be7448668b19b002n/a Heodo
2020-01-15attachment.docdoc 1fa6b7a7605dc661da0153aeb358bb43dece920fd742c3dd961919856a5fa69aVirustotal results 33.33% Heodo
2020-01-15Attachment-59609136 9530.docdoc 7295c628c5a8c7d747f2a1108316b2c182034558ccdabc495e8a4f5beaf5771cVirustotal results 31.15% Heodo
2020-01-15UNTITLED_5051648 586.docdoc 9362ae0daf8aecc19d3b8e7935cf1073616730a03ed86f12d5389b13f5ca2fa5Virustotal results 29.51% Heodo
2020-01-15Attachment_864791.docdoc 87c8765523549bffda97b2026e7d94acad88047515f157001ca32b3b7c778f54n/a Heodo
2020-01-15Attachments-8106468527-10218.docdoc 3b3388c5f0830c3beaed1ffcafef5d5a5a63e4e7c7ac455a401d15745f9c4b6cVirustotal results 30.65% Heodo